Privacy Policy
Version 1.7 — Last updated: September 13, 2026
This Privacy Policy describes how BAGHOLDER ("we," "us," or "our")
collects, uses, and protects your information when you use our
mobile application.
Information Stored on Your Device
BAGHOLDER stores the following data locally on your device using
encrypted storage (iOS Keychain / Android Keystore for secrets,
an encrypted local database for structured data):
- Your bags and token lists
- Purchase history and pending orders
- Send records, including the addresses you send to (stored with
your send records and carried in your encrypted backup)
- Blocked-attempt audit log (kept for 365 days for
support purposes; a structured mirror is also stored
on our server — see below)
- Portfolio snapshots
- Diagnostic logs
- State of residence
- Date of birth verification status
- Wallet address
- App settings and preferences
- Disclosure and terms acceptance records
- Account protection data: a random identifier the app generates
for this installation (it is not a device identifier), and a
setting recording that this phone confirms sends, sales and
cash-outs with your BAGHOLDER PIN rather than Device
Authentication. Both are kept in your phone’s secure storage.
Both are sent to our server, over an encrypted connection, with
each account-protection check; the server keeps only a one-way
hash of the identifier, and that setting (see below). Your PIN
itself is not stored on your device.
Other than the blocked-attempt mirror and the account protection data
noted above,
this data is NOT transmitted to our servers and
remains exclusively on your device.
Encrypted Cloud Backup
To protect against data loss (device replacement, app reinstallation,
or accidental storage clearing), BAGHOLDER automatically creates an
encrypted backup of your on-device data. This backup is encrypted on
your device using a key derived from your wallet before transmission.
We store the encrypted data on our server but cannot decrypt,
read, or access its contents. Only your wallet can unlock
the backup.
The backup includes: your bags, your buys, your sells and cash-outs,
your token swaps, your sends (including the addresses you sent to),
stablecoin conversions, BAGHOLDER’s platform
fees, gas purchases, your app settings and your portfolio snapshots
— everything the app records on your device except caches and
in-flight queues, which are rebuilt rather than carried. An upload
follows shortly after your records change, rather than on a schedule.
It can be delayed — if you are offline, or if this device has
not yet finished restoring an existing backup — in which case
the app retries and tells you if it cannot. On reinstall or device change, signing in recovers your
wallet, which automatically decrypts and restores your data.
You can delete your backup at any time by deleting your account in
Settings.
Information Stored on Our Server
Our server stores the following data in a secured database:
- Payment profile (wallet address, transaction volume)
- Payment charge records (payment provider session ID, charge amount,
fee amount, wallet address, chain, status, timestamp)
- Gas funding records (wallet address, transaction hash,
native-token gas amount, chain, timestamp)
- Fee sweep records (chain, amount, transaction hash, fee type,
timestamp) retained indefinitely as the financial and audit
record
- Per-token swap outcomes (chain, symbol, amount, DEX used,
success/failure reason, transaction hash)
- Cached wallet token balances: our server reads the token balances
of your addresses on your behalf, covering all the coins you hold
and not only the tokens in your bags, so the app can show them, and
keeps a short-lived cache (so we do not pay third-party RPC
providers for repeat reads of the same on-chain data)
- Send check records: when you send, the recipient address and the
token are sent to our server once, to be checked against U.S.
sanctions lists. The recipient address is not
stored. We keep a record of the attempt: your wallet address, the
network, the token, the state code, and whether the send was
allowed, plus its dollar value when known.
- Account protection records, kept for the PIN and phone checks
described in the Terms of Service
(“Your PIN and Account Protection”). Per account, keyed
by your wallet address: a salted, one-way scrambled form of your
BAGHOLDER PIN (never the PIN itself), a count of wrong PIN entries
made from phones on which your PIN has never been entered and any
lock that results, the times your PIN was set or reset, which phone
asked for a reset, and when a reset was last cancelled. For the 24
hours after a reset we
also keep the scrambled form of the previous PIN, so that the reset
can be cancelled. Per phone your account is signed in on: a one-way
hash of a random identifier the app generates (not a device
identifier), computed together with your account, so the same phone
signed in to two accounts has a different stored value on each;
whether it is an Android phone or an iPhone; when it was first and
last seen; whether it is trusted or frozen; whether the app found
that phone with no screen lock; and a count of wrong PIN entries
made on that phone and any lock that results. When an account has
more than six of these phone records, those for phones on which
your PIN was never entered, which are not frozen and have not been
seen for 30 days, are deleted. Your
PIN is sent to our server over an encrypted connection to be
checked; we do not store it in a form that can be read back, and we
cannot recover it for you.
- Solana ATA membership cache (which token accounts your Solana
wallet has, so we charge the correct account-creation rent)
- Sell (cash-out) session records: the payout provider and
sub-provider identifier used, your wallet address, the chain, the
asset, the crypto amount, your chosen payout method, the state code
used for the eligibility check, an idempotency key, the provider's
transaction identifier, the redirect link to the provider's page,
the status, and any error text returned to us. As the sell
progresses we also record what the provider reports back: its own
status, the fiat payout amount and currency, the provider's fee,
the settled crypto amount, the deposit transaction hash, and
timestamps. These records contain no personal information
beyond your wallet address and state code — the same
categories as a payment charge record.
- Sell fee records, created only when a BAGHOLDER sell fee applies
to a sell: your wallet address, the chain, the asset, the gross and fee amounts in that asset, the fee rate, the price reference used, the fee transaction hash and nonce, the amount verified on-chain, the status (armed, verified, or skipped and why), the sell disclosure version and fee label you accepted, the payout session reference, and any refund transaction hash. These records contain
no personal information beyond your wallet address.
- Payout provider webhook records: the raw notification body a
payout provider sends us about your order, stored so that we
process each notification exactly once and ignore duplicates. This
body can contain your wallet address and the amounts involved. It
does not contain identity documents.
- Per-state activity aggregates and snapshots: rolling-12-month
totals of purchase volume, completed cash-out (sell) volume,
platform fees, purchase count, and
active-user count, broken out by the state code recorded on each
transaction. Used to monitor compliance with state-level thresholds
such as California Financial Code §3103(b)(9). A completed
sell counts toward these totals on the same basis as a purchase. A
snapshot of
these aggregates is persisted to a separate table approximately
once per calendar quarter, to provide a historical record of
what we knew when. The aggregates and snapshots do not contain
wallet addresses or individual purchase or sell records —
only state-level totals.
- Verified wallet binding pair if you bind a Solana wallet
(EVM address ↔ Solana address, signed proof)
- Wallet-to-account binding (a record linking each wallet
address you sign in with to the account identifier issued
by our wallet provider, Privy). Used to enforce the gas-
funding Sybil cap and suspension provisions described in the
Terms of Service — not a per-account limit on how much
you may purchase. No additional personal information is
collected through this binding.
- Suspended-wallet list (wallet addresses we have refused
service to, with a short text reason and timestamp). Used
to enforce the suspension provisions in the Terms of
Service. Suspension blocks only starting a new payment for a
purchase through the App, receiving network gas from
BAGHOLDER, and creating new shared bags; suspended accounts
retain the ability to export
their private keys through the wallet provider's hosted
page.
- Anonymized usage events (e.g., app opens, feature usage,
purchase outcomes) associated with your wallet address only and
automatically deleted after 1 year
- Blocked-attempt audit log mirror (chain, amount requested,
token symbols, block reason, timestamp) — required to
demonstrate compliance with state eligibility, age, and limit
rules. Retained for the regulatory window (no automatic
deletion).
- Token registry liquidity events (token de-list/re-list history
with reason — used to power the "this token was removed"
message in the app)
- Shared bag configurations (token lists only, no personal data)
if you choose to share a bag via the sharing feature. Unused
shared bags are automatically deleted after 1 year
- The encrypted cloud backup of your local
app data if you opt in — encryption key is derived from
your wallet signature and the server cannot decrypt it
- Onboarding attestation records (see below) —
the pass/fail outcome recorded at each signup gate (age, state,
and legal-document review), keyed to a device identifier rather
than your wallet, and retained for about 1 year. On a failed age
check we record only an age band, never your date of birth.
Onboarding attestation records
During signup, before you have a wallet, the App records the
pass/fail outcome at each eligibility gate (age verification, state
selection, and legal-document review) so we can maintain a
compliance audit trail and apply anti-abuse and rate-limiting
safeguards against automated or repeated evasion. These records are
keyed to a device identifier rather than your wallet, name, or
email, and are retained for about one year. On a failed age check
we record only an age band — never your date
of birth. We also record the request IP at the moment of state
attestation as a secondary cross-reference for the audit trail;
your self-attested state of residence is the primary
record. These records are never linked to your wallet,
payment, or order records, and do not include your name, email, or
any other personally identifiable information (PII).
Important: your email address may
pass through our server when you make a buy — it is
forwarded to our payment provider as required by their payment
API. The transit is encrypted (HTTPS) and the value is discarded
immediately after it's sent. No row of any database
on our server contains your email at rest.
Information We Do NOT Collect
BAGHOLDER does not store on any server:
- Private keys or wallet seed phrases
- Your name
- Your email address (passes through in-transit on each buy
only — see above)
- Date of birth (only the age band on a rejected attempt —
see "Onboarding attestation records" above)
- Biometric data (device authentication returns a boolean only)
- Bank account credentials or login information
- Social Security numbers or government IDs
- Location data (your IP address briefly touches our server
during each buy and is forwarded to our payment provider for
fraud-risk scoring — we do not log or store it; the single exception
is the attestation-event audit trail described above, which is
never linked to your wallet, payment, or order records)
Third-Party Services
BAGHOLDER integrates with third-party services that process your
data under their own privacy policies:
Payment provider
Our licensed payment provider processes your fiat payment and
delivers a USD stablecoin (currently USDC) directly to your wallet,
and performs any identity checks under its own privacy policy. You
can pay as a guest with Apple Pay, Google Pay, card, and more
depending on your provider — no account needed to get started.
On every buy we pass your wallet address, the amount, and the
destination chain to the provider; the provider collects any payment
or identity details directly from you on its own payment screen. We
receive only confirmation of successful delivery of the stablecoin.
Tax reporting: BAGHOLDER is a non-custodial software
tool and does not prepare or file tax forms on your behalf. Buying
cryptocurrency through our integrated onramp is generally not itself
a taxable event under current US tax law. But every time tokens are
swapped for other tokens — which happens automatically as part
of every BAGHOLDER buy (the stablecoin your payment bought is
swapped into the tokens you selected) — and every later sale,
cash-out, or other disposal, can be a taxable event for which you
are responsible.
BAGHOLDER does not report your transactions to any tax authority and
does not issue tax forms. Any tax form relating to your crypto
activity would come from a third party — such as the payout
provider you cash out through, or another platform where you sell
— not from BAGHOLDER.
Tax rules vary by jurisdiction and change over time — always consult
a qualified tax advisor for your specific situation.
Off-ramp payout provider (selling)
Where selling is available, your cash-out is handled by a third-party
payout provider — today Transak, reached
through the Coindisco aggregator. The provider
verifies your identity on its own hosted page, under
its own privacy policy. It collects your identity
documents and payout details directly from you —
typically a government photo ID, your Social Security number, a
selfie, and your card details. BAGHOLDER never receives,
sees, forwards, or stores any of it, and no BAGHOLDER
database has a column for it.
We do not send the provider your name or email
address on a sell. We send only what is needed to price and create
the order: the chain, the asset, the amount, the payout method, the
state code, and your wallet address. Your IP address is forwarded in
the request header so the provider can run its own geography and
fraud checks — it passes through only; we do not log or store
it, and no sell record has an IP column.
We receive back only the order status, the fiat payout amount and
currency, the provider's fee, the settled crypto amount, and the
deposit transaction hash. BAGHOLDER is not the buyer or the seller,
never receives the crypto you sell or the cash you are paid, and
cannot reverse a transfer. See
Terms of Service §7.1.
Privy (wallet creation)
Privy creates and manages your non-custodial embedded wallet using
advanced cryptographic techniques. Privy may collect your email
address or social login credentials for authentication. We do not
receive or store these credentials.
See: privy.io/privacy
Firebase Crashlytics (crash reporting)
We use Google's Firebase Crashlytics for crash reporting. When
the app crashes, Crashlytics sends Google a crash report that
includes a Crashlytics Installation UUID (an anonymous identifier
Google generates per app install — not linked to any account
or wallet on our side), your IP address (used by Google for
geographic crash distribution and discarded afterward), the stack
trace and exception details, device model, and OS version. We
strip wallet addresses and Solana addresses from error messages
before sending. Crash reports do NOT contain your name, email,
phone, or wallet address.
See: firebase.google.com/support/privacy
Blockchain infrastructure providers (RPC)
Third-party providers relay blockchain data between your wallet and
the network. They may see your wallet address in transaction requests.
No personal data is shared beyond the wallet address.
Jupiter (Solana DEX aggregator)
For purchases on Solana, our server sends your swap parameters
(input token, output token, amount, your wallet address) to
Jupiter's public aggregator API so it can return a routed swap
transaction your wallet then signs. Jupiter sees only the wallet
address and swap parameters.
See: jup.ag/legal/terms-of-use
CoinGecko (market data)
We fetch public cryptocurrency market data from CoinGecko. No user
data is shared with CoinGecko.
DefiLlama (near-live prices)
We fetch public near-live token prices from DefiLlama, keyed only by
the token identifier. No user data is shared with DefiLlama.
Data Retention
- Local data: stored until you delete your account or uninstall
the app.
- Server payment records, gas funding records, fee sweep records,
swap fee and swap check records, and send check records: retained indefinitely as the
financial and audit record, for tax and accounting purposes.
- Swap event logs: up to 1 year, then deleted. Error reports: up to
90 days, then deleted. Both are deleted on account deletion.
- Payment profiles: retained while your wallet is active.
- Account protection records (the scrambled form of your PIN, and
the records of the phones your account is signed in on): retained
while your account is active, deleted on account deletion; some
phone records are deleted earlier, as described above.
- Anonymized usage events: retained for 1 year, then
automatically deleted.
- Shared bag configurations: automatically deleted after 1 year
of inactivity.
- Blocked-attempt audit log: retained on your device for 365
days, then automatically pruned.
- Sell (cash-out) records where the order was created: retained
indefinitely as the financial and audit record, on the same basis
as payment charge records. The wallet address is retained raw and
replaced with a one-way hash on account deletion.
- Sell fee records: retained indefinitely as the financial and audit
record, on the same basis as sell records. The wallet address is
retained raw and replaced with a one-way hash on account deletion,
when the fee and refund transaction hashes are also cleared.
- Sell records where creation failed before the order reached the
provider: deleted after 90 days. A sell whose outcome we could not
confirm is kept, because deleting a record of a
transfer that may have happened would destroy the audit trail.
- Payout provider webhook records: the raw body is blanked 30 days
after the notification is processed, and the record itself is
deleted after 180 days.
Your Rights
You have the right to:
- Export your account’s keys at any time from Settings, to use
them in a wallet app of your choice.
- Delete your account using the Delete Account feature in Settings.
Our server is cleaned up first: your encrypted
backup and its history, shared bags, wallet bindings, caches, swap
event logs, error reports and your account protection records (the
scrambled form of your PIN and the records of the phones your
account is signed in on) are deleted. If our server cannot be
reached or any step fails, nothing is deleted and the app asks you
to try again. Then all data on your phone is erased and your wallet
session is disconnected. Your wallet and coins are not deleted: they
remain yours on the blockchain. Your Privy login is not deleted;
signing in again with the same login reopens the same wallet
(contact Privy to delete the login itself). Financial records we
are required to keep — payment charges, treasury ledger, gas
fundings, usage events, sell (cash-out) records, sell fee records,
swap fee and swap check records, and send check records — are
kept, with your
wallet address removed and replaced by a keyed one-way hash. Their
amounts, dates, chain and state code remain, so this removes your
address but is not full anonymization. For
sell records we additionally clear the provider link, the
provider's transaction identifier, any error text, and the deposit
transaction hash, and we blank the stored provider webhook bodies
that referenced you. For sell fee records we clear the fee
transaction hash and any refund transaction hash.
- View your transaction history at any time within the app.
- Request deletion of server-stored data by contacting us at
support@getbagholder.com.
California Residents (CCPA)
If you are a California resident, the California Consumer Privacy
Act (CCPA) provides you with additional rights:
- Right to know what personal information we collect and how it
is used.
- Right to delete your personal information.
- Right to opt out of the sale of your personal information.
We do NOT sell your personal information.
- Right to non-discrimination for exercising your rights.
- Right to correct inaccurate personal information.
- Right to limit use of sensitive personal information. We do not
collect sensitive personal information.
To exercise these rights, contact us at
support@getbagholder.com.
Geographic Availability
BAGHOLDER is available in 41 U.S. states. BAGHOLDER is not available
in New York, Connecticut, Louisiana, Vermont, New Mexico,
the District of Columbia, Pennsylvania, Oregon, Arkansas, or West
Virginia.
Children's Privacy
BAGHOLDER is not intended for anyone under the age of 18. We do
not knowingly collect personal information from children under 18.
If we become aware that a child under 18 has provided us with
personal information, we will take steps to delete such information.
Security
We use industry-standard security measures to protect your data,
including:
- Encrypted local storage (iOS Keychain / Android Keystore)
- HTTPS for all server communication
- Advanced cryptographic key management via our wallet provider
- API keys stored server-side only, never on your device
No system is 100% secure. You are responsible for securing access
to your device.
Changes to This Policy
We may update this privacy policy from time to time. The current
version is always available in the app under Settings. If we make
material changes, you will be asked to review and accept the
updated policy.
Contact Us
If you have questions about this privacy policy, contact us at:
support@getbagholder.com
getbagholder.com